PHPÉú³É¾²Ì¬htmlÍøÒ³µÄÈýÖÖ·½·¨
PHPÉú³É¾²Ì¬htmlÍøÒ³µÄÈýÖÖ·½·¨
¡¾×ª×Ô¡¿ http://hi.baidu.com/chuanqi%5Fding/blog/item/8a97e8d6f3232c2a07088b1b.html
µÚÒ»ÖÖ£ºÀûÓÃÄ£°å¡£Ä¿Ç°PHPµÄÄ£°å¿ÉÒÔ˵ÊǺܶàÁË£¬Óй¦ÄÜÇ¿´óµÄsmarty£¬»¹Óмòµ¥Ò×ÓõÄsmarttemplateµÈ¡£ËüÃÇÿһÖÖÄ£°å£¬¶¼ÓÐÒ»¸ö»ñÈ¡Êä³öÄÚÈݵĺ¯Êý¡£ÎÒÃÇÉú³É¾²Ì¬Ò³ÃæµÄ·½·¨£¬¾ÍÊÇÀûÓÃÁËÕâ¸öº¯Êý¡£ÓÃÕâ¸ö·½·¨µÄÓŵãÊÇ£¬´úÂë±È½ÏÇåÎú£¬¿É¶ÁÐԺá£
PHP´úÂë¾ÙÀý£º
<?php
require('smarty/Smarty.class.php');
$t = new Smarty;
$t->assign("title","Hello World!");
$content = $t->fetch("templates/index.htm");
//ÕâÀïµÄ fetch() ¾ÍÊÇ»ñÈ¡Êä³öÄÚÈݵĺ¯Êý,ÏÖÔÚ$content±äÁ¿ÀïÃæ,¾ÍÊÇÒªÏÔʾµÄÄÚÈÝÁË
$fp = fopen("archives/2005/05/19/0001.html", "w");
fwrite($fp, $content);
fclose($fp);
?>
µÚ¶þÖÖ·½·¨£ºÀûÓÃobϵÁеĺ¯Êý¡£ÕâÀïÓõ½µÄº¯ÊýÖ÷ÒªÊÇ ob_start(), ob_end_flush(), ob_get_content(),ÆäÖÐob_start()ÊÇ´ò¿ªä¯ÀÀÆ÷»º³åÇøµÄÒâ˼£¬´ò¿ª»º³åºó£¬ËùÓÐÀ´×ÔPHP³ÌÐòµÄ·ÇÎļþÍ·ÐÅÏ¢¾ù²»»á·¢ËÍ£¬¶øÊDZ£´æÔÚÄÚ²¿»º³åÇø£¬Ö±µ½ÄãʹÓÃÁËob_end_flush().¶øÕâÀï×îÖØÒªµÄÒ»¸öº¯Êý£¬¾ÍÊÇob_get_contents(),Õâ¸öº¯ÊýµÄ×÷ÓÃÊÇ»ñÈ¡»º³åÇøµÄÄÚÈÝ£¬Ï൱ÓÚÉÏÃæµÄÄǸöfetch(),µÀÀíÒ»ÑùµÄ¡£
PHP´úÂë¾ÙÀý£º
<?php
ob_start();
echo "Hello World!";
$content = ob_get_contents();//È¡µÃphpÒ³ÃæÊä³öµÄÈ«²¿ÄÚÈÝ
$fp = fopen("archives/2005/05/19/0001.html", "w");
fwrite($fp, $content);
fclose($fp);
?>
·½·¨Èý£ºÏÂÃæ×ªÌùÒ»¸ö±È½ÏͨÓÃÇҺö®µÄ
ǰÑÔ£º
Ä¿Ç°ÍøÂçÉϺöàÍøÕ¾µÄÐÂÎÅ·¢²¼ÏµÍ³¶¼²ÉÓÃÁ˶¯Ì¬·þÎñÆ÷¼¼ÊõÉú³É¾²Ì¬HTMLµÄ×ö·¨£¬ÕâÑù×öµÄºÃ´¦ÊÇ£ºÒ»ÊÇÄܼõÇáÆä·þÎñÆ÷µÄ¸ºµ££¬¶þÊÇÒòΪÉú³ÉÁËHTML¾²Ì¬Ò³Ã棬ËùÒÔÆäÍøÕ¾±»ËÑË÷ÒýÇæËÑË÷µ½µÄ»úÂʸü´óһЩ¡£±ÊÕßµÄÍøÕ¾Ôø¾Ê¹ÓÃPHPÕâÒ»¶¯Ì¬¼¼ÊõÀ´¹¹½¨ÐÂÎÅ·¢²¼ÏµÍ³£¬ÆäÔÀíÒ²¾ÍÊÇÓ¦ÓÃÁËPHPÉú³ÉHTML¾²Ì¬Ò³ÃæµÄ¼¼Êõ£¬Ïà¹ØÆ½Ì¨ÊÇ Windows XP Sp2+php4.32+mysql£¬Òò´Ë£¬ÔÚÕâÀÏë¼òµ¥µØÌ¸Ò»ÏÂÕâÖÖ×ö·¨µÄ˼·¡£ÕâÆªÎÄÕÂÊʺÏÓÚ¶ÔPHP+MYSQLÊý¾Ý¿â²Ù×÷£¬SQLÓï¾äÒÔ¼°ÍøÒ³Éè¼ÆÓеã»ù´¡µÄÅóÓÑ£¬Èç¹ûÄúÊÇÒ»¸ö´ÓÍ·¿ªÊ¼Ñ§µÄÅóÓÑ£¬ÄÇôÇëÏÈ´òºÃ»ù´¡°É£¡µ½ÕâÀï¾Í²»ÓÃÍùÏ¿´ÁË¡£Èç¹ûÄú¶¼·ûºÏÉÏÊöÌõ¼þµÄ»°£¬ÄÇô¹§Ï²Äú£¬Çë½Ó×ÅÍùÏ¿´¡£µ«ÊÇ£¬ÔÚ¾ßÌ嶯ÊÖ¹¹½¨Ö®Ç°£¬Äú»¹Òª×öºÃÒÔϼ¸µã×¼±¸¹¤×÷¡£
Ò»¡¢ ¾ß±¸±¾µØµ÷ÊÔPHPµÄ¹¦ÄÜ
ÔÚWINDOWS XP²Ù×÷ϵͳÏ£¬±ÊÕß½¨ÒéÄ
Ïà¹ØÎĵµ£º
Php×¢Èë¹¥»÷ÊÇÏÖ½ñ×îÁ÷ÐеĹ¥»÷·½Ê½£¬ÒÀ¿¿ËüÇ¿´óµÄÁé»îÐÔÎüÒýÁ˹ã´óºÚÃÔ¡£
ÔÚÉÏÒ»ÆÚµÄ¡¶php°²È«Óë×¢ÉäרÌâ¡·ÖÐÁÖ.linxÖ÷Òª½²ÊöÁËphp³ÌÐòµÄ¸÷ÖÖ©¶´£¬Ò²½²µ½ÁËphp£«mysql×¢ÈëµÄÎÊÌ⣬¿ÉÊǽ²µÄ×¢ÈëµÄÎÊÌâ±È½ÏÉÙ£¬ÈÃÎÒÃǸоõûÓо¡ÐËÊǰÉ.
OK,ÕâÒ»ÆÚÎÒ½«¸ø´ó¼Ò»ï×Ð×ÐϸϸµÄ´µÒ»´µphp£«mysql×¢È룬һ¶¨ÈÃÄãÂúÔØ¶ø¹éŶ ......
1¡¢¹ÅÀÏµÄÆÛÆSQLÓï¾ä
ÔÚĬÈÏģʽÏ£¬¼´Ê¹ÊÇÄãÍüÁ˰Ñphp.ini¿½µ½/usr/local/lib/php.iniÏ£¬php»¹ÊÇ´ò¿ªmagic_quotes_gpc=on¡£
ÕâÑùËùÓдÓGET/POST/CookieÀ´µÄ±äÁ¿µÄµ¥ÒýºÅ(')¡¢Ë«ÒýºÅ(")¡¢·´Ð±¸Übackslash(\)ÒÔ¼°¿Õ×ÖÔªNUL
(the null byte)¶¼»á±»¼ÓÉÏ·´Ð±¸Ü£¬ÒÔʹÊý¾Ý¿âÄܹ»ÕýÈ·²éѯ¡£
µ«ÊÇÔÚphp-4-RC2µÄʱºòÒýÈë ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°
£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......
php ¹ºÎﳵʵÀý
<?php
/**
php ¹ºÎﳵʵÀý
ÍøÉÏËѵ½µÄ£¬¼òµ¥ÈÝÒ×Àí½â¡£cookie´æ¹ºÎï³µID£¬db´æ¹ºÎï³µÊý¾Ý¡£ ¹ºÎï³µsessionµÄ²úÉú´úÂë
*/
if(! $session && ! $scid) {
/*
sessionÓÃÀ´Çø±ðÿһ¸ö¹ºÎï³µ£¬Ï൱ÓÚÿ¸ö³µµÄÉí·ÝÖ¤ºÅ£»
scidÖ»ÓÃÀ´±êʶһ¸ö¹ºÎï³µidºÅ£¬¿ÉÒÔ¿´×öÊÇÿ¸ö³µµÄÃû×Ö£»
......
ҪʹÄúµÄFCKeditorÄܹ»Ê¹ÓÃÉÏ´«¹¦ÄÜ£¬Äú±ØÐë½øÐÐÒÔÏÂÅäÖÆ¡£
×¢Ò⣺FCKeditor²»Ö§³ÖÐéÄâĿ¼£¬ÄúµÄ·¾¶ÉèÖö¼ÊÇÕë¶ÔÍøÕ¾¸ùĿ¼µÄ¾ø¶Ô·¾¶¶øÑԵġ£Õâµã¶ÔÓÚ·¢²¼µ½Ô¶³ÌÍøÕ¾Ä¿Â¼µÄ¿ª·¢Õß¼«Îª²»±ã£¬ºóÃæÎÒÃÇ»á¶Ô´Ë½øÐÐÌÖÂÛ¡£
Ò»¡¢´ò¿ªfckeditor\editor\filemanager\upload\php\config.php£¬ÕÒµ½´úÂë$Config['Enabled']£¬½«Öµ ......